Legal
Privacy Policy
This policy explains the limited information XEROVPN needs to operate a VPN service, which traffic categories we do not log, how long records remain, and the controls available to you.
Effective August 22, 2026 · Last updated August 23, 20261. Who we are
XEROVPN is operated and published by Metafour LLC ("Metafour," "we," "us"). Metafour provides the XEROVPN apps, website, and VPN service. Privacy and data-rights questions can be sent to support@xerovpn.com.
2. Information we collect
Account and authentication data
- Email address: optional. Guest mode does not require an email. If you link an email, we use it for one-time sign-in codes and service messages.
- Account identifiers: internal account and account-number identifiers generated by XEROVPN.
- Google sign-in: if selected, Google supplies a stable account identifier, email address, and whether Google has verified that address. XEROVPN does not request the Google profile scope or receive your profile name.
- Sign-in security records: sign-in email, source IP, user-agent, device identifier, authentication method, time, and outcome. These records help detect fraud and account takeover.
Device and VPN configuration data
- A random app-generated device identifier, device name/type, app version, and operating-system information needed to display and manage your devices.
- The public half of the WireGuard key pair generated by the app. The private key stays on your device and is not sent to XEROVPN. A manually downloaded configuration is an exception: its pair is generated for that one-time download, and the server retains only the public key.
- When Android push delivery is available, Firebase Cloud Messaging processes a push token and Firebase installation identifier, notification contents, app version, and automatic app/device metadata such as operating-system version, device model, brand and form factor, install source, and Firebase SDK versions. This is used for app functionality and compatible push delivery. Notification payloads may contain service or account-alert text, but never browsing or tunnel traffic data.
- On Android, the Play install-referrer value is read once to apply a referral code when you followed a referral link.
Connection and network-operation records
When a VPN connection is provisioned, we temporarily record the selected VPN node and region, tunnel IP address, WireGuard public key, protocol variant, source IP address, source country derived locally from that IP, and an expiry time. This lets the network route the tunnel, apply device and concurrency limits, investigate abuse, and alert you to unexpected connection countries.
VPN nodes report cumulative bytes sent and received per public key, normally about once per minute. We use transfer volume to enforce free-plan limits, calculate capacity, and detect abuse. Paid unlimited plans are not charged against a monthly account data cap.
Required plan and service-integrity records
Separate from the optional app-interaction analytics below, our backend records monthly usage/limit snapshots and events when a plan cap or throttle state changes. These records can include the internal account identifier while the account is active, plan and cycle information, byte totals and limits, throttle reason/source, and timestamps. We use them to enforce plan and anti-abuse rules and to analyze capacity and plan performance. They are required for operating the service and are not controlled by the optional product-analytics setting. On account deletion, the account identifier is removed from these records where supported; the resulting history ages out under the 400- or 730-day limits in Section 7.
Application and infrastructure logs
To operate, secure, and troubleshoot the service, XEROVPN and its infrastructure providers process limited logs such as time, operation or route, result/status, error details, counts, and pseudonymous account, device, or node references when needed. Reverse proxies and hosts necessarily process request metadata and a source IP. We minimize these records and do not intentionally place full email addresses, Play purchase tokens, WireGuard public keys or allowed IPs, authentication secrets, support-message text, or VPN browsing destinations in ordinary application logs.
Optional product analytics
The apps can send a small, fixed set of app-interaction events to XEROVPN's own servers: for example, viewing the paywall, tapping an upgrade action, completing a purchase, connecting or disconnecting, using a feature, sharing a referral, or viewing a day pass. An event can include its source, product context, app version, client timestamp, and the account/device identifiers associated with the authenticated request.
These events never include your email, browsing history, DNS queries, traffic contents, a VPN destination/domain, or a raw IP address in the event body. On Android, product analytics is off unless you explicitly enable it under Settings → Privacy & Security. The current iOS app exposes an equivalent control but currently defaults it on, so you must turn it off if you do not want iOS product events collected. Turning the setting off clears queued events and stops new collection; a request already accepted by our server cannot be recalled.
Android crash and ANR diagnostics
Production Android builds automatically send crash and application-not-responding diagnostics to Sentry so we can find and repair reliability problems. A report can contain an exception type, application stack traces and thread state, the XEROVPN app version/build and release channel, whether the app was in the foreground, and the Android name/version. This required diagnostic collection is separate from optional product analytics.
Before transmission, the app removes free-form exception messages and thread names, user and request objects, account and device identifiers, email, server name, breadcrumbs, custom tags and extras, detailed device context, screenshots, view hierarchy, replay, profiling, and performance traces. The app does not use Sentry for product-interaction events. Sentry necessarily receives a network connection to accept the report. Production Android release builds are blocked unless the Sentry project has IP-address storage and raw crash-report storage disabled. Crash diagnostics never include VPN browsing history, DNS queries, destination addresses, or traffic contents.
User-initiated support email
On Android, Report an issue opens your external email app with an editable draft addressed to XEROVPN. Nothing is sent to XEROVPN merely by opening the draft. If you choose to tap Send, we and the email providers handling the message receive your sender address and ordinary email-routing metadata, the text you write, and any diagnostic fields you leave in the draft.
The prefilled diagnostic snapshot is limited to the app build and release channel; whether an app session is present and is a guest session; plan, selected region, VPN state, active transport, selected node/location label, and split-tunnel status/count; latency, jitter, reachability, handshake age, current-session byte total, and the aggregate count of trackers blocked in that session. The prefilled draft excludes your XEROVPN account email, app-generated device ID, public IP address, VPN endpoint address/host, and in-memory session log. You can review or delete any part before sending. If no email app is available, Android copies the same unsent draft to your clipboard for you to control.
Billing and service records
- Your plan, entitlement status, renewal/expiry date, and payment-provider identifiers.
- Google Play purchase tokens and signed purchase state, Apple signed transaction records, or Stripe customer/subscription/payment identifiers. XEROVPN does not receive or store your full card number.
- Payment disputes, account alerts, abuse markers, saved server favorites, referral codes, and referral-redemption evidence needed to prevent repeat rewards.
3. Information we do not log or retain
- Websites, hostnames, destination IP addresses, or destination ports accessed through the tunnel.
- Per-user DNS query history or browsing history. A resolver can transiently cache DNS answers to provide the live service, but XEROVPN does not retain a DNS query log.
- VPN packet contents or the contents of communications carried through the tunnel.
- Advertising identifiers, IMEI, hardware serial numbers, contacts, photos, files, or precise device location. We do not read your inbox, SMS/MMS, or unrelated messages; the only message content we receive is what you choose to send to support.
We deliberately do not describe the service as "zero logs." The operational, metering, authentication, and billing records above exist. What we do not keep is a record of where your traffic went or what it contained.
4. DNS
With tracker blocking enabled, DNS requests travel through the VPN tunnel to the resolver on the selected VPN node. Query logging is disabled. External lookups are forwarded over encrypted DNS to upstream resolvers operated by Cloudflare and Google and appear to originate from the VPN node, not your source IP.
With tracker blocking disabled, DNS travels through the tunnel to the configured resolver, which is Cloudflare by default unless you select a custom resolver. In rare resolution failures, an app may fall back to Cloudflare so the connection remains usable. XEROVPN does not log DNS queries on either path.
5. How we use information
- Provide, secure, troubleshoot, and improve the VPN service.
- Authenticate users and manage accounts and devices.
- Route VPN connections and enforce plan, device, concurrency, and abuse limits.
- Process purchases, subscriptions, refunds, and payment disputes.
- Send transactional messages and requested notifications.
- Meet legal obligations and respond to valid legal process.
6. Service providers and sharing
We do not sell personal data and do not share it with advertisers, data brokers, or third-party analytics networks. The following providers process limited information for us:
| Provider | Information and purpose |
|---|---|
| Resend | Email address and transactional email contents, including a requested one-time sign-in or email-change code. |
| Google sign-in when selected; Google Play Billing purchase verification; and, when Android push is available, Firebase Cloud Messaging processing of the push token, Firebase installation identifier, notification contents, app version, and the automatic app/device metadata described above. | |
| Apple | StoreKit processes iOS purchases and supplies signed transaction and renewal records for entitlement verification. DeviceCheck receives a short-lived Apple device token, a per-request transaction identifier and timestamp, and two anti-abuse state bits to limit repeat free-tier claims; it does not return a device identifier to XEROVPN. |
| Stripe | Payment, customer, and subscription identifiers, an internal account reference, and email entered at checkout for card billing. |
| Sentry | Data-minimized Android crash and application-not-responding diagnostics described above, used only to diagnose app reliability. Sentry acts as our service provider. |
| Proton Mail and your email provider | Proton Mail routes and stores messages sent to XEROVPN support. Proton Mail and the provider you use to send the message process your sender address, ordinary email-routing metadata, your text, and any limited diagnostic fields you leave in the editable draft. |
| Cloudflare and Google DNS | DNS requests originating from a VPN node as described in Section 4, without your source IP. |
| Infrastructure providers | Systems that host our API and VPN nodes. Tunnel traffic traverses a selected node but is not logged as browsing activity by XEROVPN. |
We may disclose information when required by valid legal process, to protect users or the service from fraud or abuse, or as part of a business transaction subject to appropriate confidentiality and notice. Because XEROVPN does not retain browsing destinations or traffic contents, we cannot provide records we do not have.
7. Retention
| Record | Typical retention |
|---|---|
| One-time codes and Google sign-in flows | Expire after approximately 10–15 minutes; expired rows are purged within 8 days. |
| Device-pairing codes | Removed after the short code and any claimed exchange token have expired; the cleanup runs about every 5 minutes. |
| Sign-in and free-grant security evidence | 90 days. Free-grant evidence can include a source IP and app-generated device identifier after the related account is deleted. |
| Referral-redemption anti-abuse ledger, including recorded source IP and app-generated device identifier | No automatic expiry currently because deletion could enable reward laundering. We are setting a proportionate legal/product retention period. |
| Connection records | Can be renewed while a connection is active and are normally removed within 24–48 hours after inactivity or disconnection; manually downloaded configurations can remain valid for 30 days. Expired records are removed by cleanup jobs. |
| Peer-removal records | A revoked peer remains pending while removal from the VPN node is retried; there is no fixed maximum before the node confirms teardown. The confirmed tombstone is then retained for 30 days. |
| Live transfer counters | Until the corresponding connection record is removed, normally no more than 24–48 hours after last activity. |
| Raw bandwidth samples / daily public-key totals | 7 days / 365 days. |
| Optional product-analytics events | 180 days, or earlier when the associated account is deleted. |
| Android crash and ANR diagnostics in Sentry | No more than 90 days. The production release is blocked unless the operator attests that configured retention is within this limit. |
| Support emails and included limited diagnostics | Until the issue is resolved, then deleted within 30 days. We may keep a message longer only when reasonably necessary for a security incident or legal obligation. |
| Ordinary application and infrastructure logs | No more than 30 days in active logs; archived provider copies expire within 90 days. A record isolated for a security incident or legal hold can remain longer only while necessary and is subject to periodic review and a deletion trigger. |
| Encrypted database backups and point-in-time-recovery copies | Expire within 30 days. Deleted production data may remain inside a recovery copy until that copy's scheduled expiry; it is not used for normal service. A restore must replay subsequent transaction records so deletions are applied before the database serves traffic. |
| Guest account | Automatically deleted after about 24 hours of inactivity; a never-used guest is usually removed sooner. |
| Account, devices, entitlements, favorites, alerts | For the life of the account, unless a shorter period above applies. |
| Administrative and node audit records | 365 days. |
| Pseudonymized or de-linked security and plan-integrity records | Depending on the record, up to 400 or 730 days after account deletion. |
| Payment disputes, referral-redemption evidence, and grant-ledger evidence | As necessary for financial record-keeping, preserving referral limits, settling outstanding rewards, fraud prevention, and preventing replay of grant operations. Some referral and grant-ledger evidence currently has no automatic expiry. |
Retention cutoffs are enforced by scheduled cleanup jobs. A record that reaches its cutoff can remain until the next scheduled run, and a failed or backlogged cleanup is retried on a later run. Production configuration is not allowed to disable these workers.
8. Account deletion and your choices
You can permanently delete an email-linked or guest account in the app under Settings → Account management → Delete account. You can also request deletion without the app at xerovpn.com/delete-account.
Deletion removes the account record, email, device credentials, VPN keys, active connection records, entitlements, subscriptions stored by XEROVPN, favorites, alerts, and your personal referral code. Deleting the XEROVPN record does not by itself cancel a subscription managed by Google Play, Apple, or Stripe; cancel that recurring subscription with its payment provider.
Limited security, metering, financial, pseudonymized, and anti-abuse records can remain for the periods in Section 7. Deleted production data can also remain in an encrypted database recovery copy until that copy expires within 30 days; it is not available to the normal service, and a restore must replay subsequent transaction records so deletions are applied before the database serves traffic. A guest can delete the current guest account while its authenticated app session is active. Inactive guest accounts are also removed automatically.
To request access to or correction of account information, or exercise a privacy right available where you live, email support@xerovpn.com from the address associated with the account. We may need to verify that you control the account before acting.
9. Security
App-to-service traffic uses TLS and VPN traffic uses WireGuard or AmneziaWG encryption. One-time codes are stored as hashes. App-generated WireGuard private keys remain on the device in protected storage and are excluded from ordinary cloud backup. We use access controls, audit records, and operational safeguards appropriate to the service. No system can be guaranteed perfectly secure; report a suspected security issue to support@xerovpn.com.
10. International processing
XEROVPN operates infrastructure in multiple countries. Information described in this policy may be processed where XEROVPN and its providers operate, subject to applicable data-protection requirements. Selecting a VPN region routes your encrypted tunnel through a node in that region.
11. Children
XEROVPN is not directed to children under 13 or the higher minimum age required where they live. If you believe a child has provided account data, contact us and we will investigate and delete it when appropriate.
12. Changes
We will post updates at this URL and update the date above. We will provide advance notice through the app or email when a change materially affects how we use personal information, unless an earlier change is required for security or legal reasons.
13. Contact
Operator: Metafour LLC
Email: support@xerovpn.com
Account deletion: xerovpn.com/delete-account